Forwarded TWCERT/CC Cybersecurity Message Alert TWCERTCC-200-202610-00000001
【CVE-2026-7273】Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability (CVSS v3.1: 8.8)
【Exploited by Ransomware: Unknown】 A stack-based buffer overflow vulnerability exists in the CGI program of Zyxel GS1900 series switches, which may allow an unauthenticated
LAN attacker to execute operating system commands via a specially crafted HTTP request.
【CVE-2026-93952】Arista VeloCloud Orchestrator Improper Input Validation Vulnerability (CVSS v3.1: 10.0)
【Exploited by Ransomware: Unknown】 The on-premises deployment of Arista VeloCloud Orchestrator contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functions, potentially compromising the confidentiality, integrity, and availability of the Orchestrator and the data it manages.
【CVE-2026-94127】F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 F5 BIG-IP APM contains a heap-based buffer overflow vulnerability. When a virtual server is configured with access policies and an OAuth profile, an unauthenticated attacker may exploit this vulnerability to achieve remote code execution.
【CVE-2026-93616】Check Point Multiple Products Path Traversal Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 Path traversal vulnerabilities exist in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, which may allow an unauthenticated attacker to upload and execute arbitrary scripts.
【CVE-2026-85102】Check Point Multiple Products Improper Certificate Validation Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 Improper certificate validation vulnerabilities exist in Check Point Security Gateway and Check Point Spark Firewall when using Site-to-Site VPN or Remote Access VPN, which may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
【CVE-2026-5430】WSO2 Multiple Products Path Traversal Vulnerability (CVSS v3.1: 10.0)
【Exploited by Ransomware: Unknown】 Path traversal vulnerabilities exist in WSO2
API Control Plane,
API Manager, Traffic Manager, and Universal Gateway, which may allow unrestricted file uploads, leading to remote code execution.
【CVE-2026-71362】Adobe Commerce and Magento Incorrect Authorization Vulnerability (CVSS v3.1: 9.1)
【Exploited by Ransomware: Unknown】 Adobe Commerce and Magento contain an incorrect authorization vulnerability that may allow an attacker to access sensitive resources with elevated privileges without any user interaction.
【CVE-2026-67279】Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability (CVSS v3.1: 6.5)
【Exploited by Ransomware: Unknown】 MikroTik RouterOS contains an improper enforcement of behavioral workflow vulnerability that may allow an unauthenticated client to open a session channel and send execution requests.
【CVE-2026-65660】Microsoft SharePoint Code Injection Vulnerability (CVSS v3.1: 8.8)
【Exploited by Ransomware: Unknown】 Microsoft SharePoint contains a code injection vulnerability that may allow an authenticated attacker to execute code over the network.
【CVE-2026-87902】WordPress Core Remote File Inclusion Vulnerability (CVSS v3.1: 8.1)
【Exploited by Ransomware: Unknown】 WordPress Core contains a remote file inclusion vulnerability that may allow an unauthenticated attacker to make the page template parsing mechanism include a readable local .php file, leading to remote code execution.
【CVE-2026-88772】Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVSS v3.1: 8.1)
【Exploited by Ransomware: Unknown】 Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that may allow an attacker to remotely execute code or cause a denial of service.
【CVE-2026-88771】Citrix NetScaler Improper Input Validation Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that may allow an unauthenticated attacker to execute arbitrary commands.